Virtualization seems to have a lot of security benefits. Rootkits can lie to DomU but not Dom0, and of course snapshotting, migration etc is *really* nice. Dom0 in OpenBSD in a current Xen implementation (with HVM) would be a dream. I'd switch wholesale, and buy a CD for every server (as I do now). But doubtless there are a whole host of issues, kernel, SMP, bootloaders (I found OpenBSDs bootloader to be superior to grub in Ubuntu 7.10, it detects media bay HDs, and the installer is fast, efficient, and doesn't crap out on certain video cards/monitors), an LVM, iSCSI support -- and I have no code to contribute, so I will merely remain hopeful without expectation. I tried NetBSD Xen, but it seemed the worst of both worlds. Pf circa 3.7, hacks for grub, old version of Xen (2.x series IIRC) without support for the most interesting features, not the same level of security focus, etc. So I just picked the best tool for the job. I'm happier our webservers are now on OpenBSD with CARP failover. -- "Invincibility is in oneself, vulnerability in the opponent." -- Sun Tzu -----Original Message----- From: Luca Corti <luca@leenoox.net> Date: Tue, 23 Oct 2007 10:03:42 To:ropers <ropers@gmail.com> Cc:Jeff Quast <af.dingo@gmail.com>, OpenBSD-Misc <misc@openbsd.org>, Nick Guenther <kousue@gmail.com> Subject: Re: About Xen: maybe a reiterative question but .. On Tue, 2007-10-23 at 01:11 +0200, ropers wrote:A proper Dom0 port of XEN to OpenBSD would solve this by removing the linux dependency. However this would probably require a significant effort on OpenBSD side and a XEN Hypervisor code audit. Also from earlier discussion on the list it seems this kind of virtualization may impact on security, which is in direct contrast with OpenBSD goals. Can someone elaborate more on this? ciao Luca
| Artem Bityutskiy | [PATCH 10/44 take 2] [UBI] debug unit implementation |
| Andrea Arcangeli | [PATCH 00 of 11] mmu notifier #v16 |
| David Brown | Re: Linux 2.6.21-rc2 |
| Ingo Molnar | [patch] softlockup watchdog: fix Xen bogosity |
git: | |
| Johannes Schindelin | Re: [PATCH 1/4] Move redo merge code in a function |
| Jeff Garzik | Re: cleaner/better zlib sources? |
| Nguyen Thai Ngoc Duy | Re: I don't want the .git directory next to my code. |
| Junio C Hamano | Re: [PATCH 2/2] git-gc: skip stashes when expiring reflogs |
| David Higgs | Re: Using the C programming language |
| Chris Bullock | OpenBSD isakmpd and pf vs Cisco PIX or ASA |
| Chris S | Re: No text cursor on OpenBSD/i386 4.1 |
| Richard Stallman | Real men don't attack straw men |
| mgrjtb | GCC 2.2.2 |
| Jojie R. T. | Re: SLS |
| Peter MacDonald | demand paging: proposal |
| C Wayne Huling | Re: Can males come from... |
| Battery Maximizer Software | 10 hours ago | Linux kernel |
| windows folder creation surprise | 11 hours ago | Windows |
| Problem in scim in Fedora 9 | 13 hours ago | Linux general |
| Firewall | 1 day ago | OpenBSD |
| IP layer send packet | 1 day ago | Linux kernel |
| dtrace for linux available | 2 days ago | Linux kernel |
| Unable to mount ramdisk image using UBoot while upgrading to 2.6.15 kernel for a MPC8540 based target | 2 days ago | Linux kernel |
| RealTek RTL8169 - can't connect | 2 days ago | NetBSD |
| vsftpd Upload Problems | 2 days ago | Linux general |
| creating con folder in desktop | 3 days ago | Windows |
